The Costly Consequences of Cyberattacks: Lessons from MGM Resorts

Last month, MGM Resorts fell victim to a devastating cyberattack that not only cost the company $100 million but also exposed the personal information of its customers. This incident serves as a stark reminder of the importance of robust cybersecurity measures and the potential risks faced by businesses operating in sectors like retail, healthcare, professional services, and financial services.

A Profitable Target for Hackers

MGM Resorts, a renowned hospitality and entertainment giant, disclosed the cybersecurity issue on September 11, 2023. The attack impacted various aspects of the company’s operations, including its main website, online reservations systems, and in-casino services like slot machines, credit card terminals, and ATMs.

Following an investigation, it was revealed that the threat actor responsible for the disruption was an affiliate of the BlackCat/ALPHV ransomware gang known as Scattered Spider. These hackers utilized social engineering techniques to breach MGM’s network, steal sensitive data, and encrypt over a hundred ESXi hypervisors.

Disrupting Business Operations

The impact of the IT system outage caused by the cyberattack was significant, leading to disruptions across a broad range of MGM’s business operations. The company estimates a negative impact of approximately $100 million to Adjusted Property EBITDAR for the Las Vegas Strip Resorts and Regional Operations.

While the availability of bookings through the company’s website and mobile applications resulted in lower occupancy rates, the financial impact was mainly contained to the month of September, accounting for 88% of the negative impact.

In addition to the $100 million in earnings lost, MGM incurred less than $10 million in one-time expenses for risk remediation, legal fees, third-party advisory, and incident response measures. Fortunately, MGM expects to be fully covered by its cybersecurity insurance.

Protecting Customer Data

One of the most concerning aspects of the cyberattack was the theft of customers’ personal information. MGM warns that the threat actors managed to steal the personal details of customers who had transacted with the company before March 2019.

The exposed information includes full names, phone numbers, email addresses, postal addresses, gender, date of birth, driver’s licenses, Social Security Numbers (SSN), and passport numbers. However, MGM asserts that the incident did not expose customer passwords, bank account numbers, or payment card information.

In response, MGM is offering free credit monitoring and identity protection services to affected individuals. The company advises customers to remain vigilant against unsolicited communications and recommends reviewing account statements and monitoring credit reports to detect any signs of fraud or identity theft.

